Legal Operating Model
- Legacy
- Matters, contracts, and reviews run manually with no AI in the workflow.
- Autonomous
- AI-native workflows compound, self-improving from every matter and contract closed.
A function-specific read on how AI is embedded, governed, and standardized across the legal and compliance team, scored from Legacy to Autonomous.
Regulators, courts, and clients now expect documented AI governance, and the legal team that polices everyone else cannot afford to run its own AI on hope.
The same five pillars of AI readiness, framed in the work, systems, and stakes that general counsel and compliance leaders actually face.
Whether AI is built into how legal work actually gets done, from intake and contract review to research and matter management, as durable shared assets rather than one associate's private prompts.
How AI changes what the function produces and whether that output is reviewed, validated, and defensible enough to file, advise on, or put in front of a regulator.
How broadly real AI fluency runs across lawyers, paralegals, and compliance staff, and whether reskilling and redefined roles are owned rather than left to a few power users.
The function's own AI policy, privilege and confidentiality controls, QC of AI output, and the regulation that touches it, applied to itself with the rigor it demands of the business.
Whether the legal AI stack and its spend are a deliberate, owned, contract-reviewed system or a sprawl of point tools nobody vetted for privilege, retention, or IP terms.
AIR places Legal & Compliance on a six-tier readiness ladder from 0 to 100, overall and for every pillar. The climb runs from digital but not intelligent, to a compounding, AI-native edge.
AI-native advantage. Compounding intelligence and speed, a durable edge competitors can't copy fast.
Woven through the business. AI shapes the operating model, pricing, and talent, and ROI is proven.
AI in the core, governed. Embedded at named steps with SOPs, policy, and measured gains.
Pockets, not a system. Real use in places, uneven and undocumented.
Experimenting at the edges. Scattered pilots that live in a few people's heads, ungoverned.
Digital, not intelligent. AI is absent or anecdotal, work is hour-priced, the stack sprawls, and no policy exists.
One score tells you that you are behind; five tiers tell you exactly where to start.
The matrix is a 5-by-6 grid: your five pillars of AI readiness scored against the same six tiers, from Legacy to Autonomous. A single overall score tells you roughly where you sit; it hides where you are dangerously behind and where you are quietly ahead. Reading a tier per pillar turns one vague number into five specific, fixable verdicts, so you act on the truth instead of an average.
How Legal & Compliance's regulatory reality maps onto AIR readiness. Each row is a control your governance pillar has to carry.
| Regime | Pillar | What AI readiness requires |
|---|---|---|
| EU AI Act | P4 | classify AI used in legal and compliance workflows by risk and maintain the documentation, human oversight, and logging the tier requires |
| NIST AI RMF 1.0 | P4 | govern, map, measure, and manage AI risk across the function with named owners and recorded decisions, not informal habit |
| ISO/IEC 42001 | P1 | run a documented AI management system with defined roles, controls, and continual improvement embedded in how the function operates |
| Attorney-client privilege and work-product doctrine | P4 | ensure AI tools and prompts do not waive privilege or expose work product, with confidentiality controls and vendor terms reviewed |
| E-discovery duties (FRCP Rule 26 / Sedona Conference) | P2 | validate, defend, and document AI-assisted review and TAR so output withstands proportionality and reasonableness challenges |
| IP ownership and vendor contract terms | P5 | confirm tool contracts settle ownership of AI output, training-data use, and indemnity before the stack is standardized |
Illustrative mapping for AI-readiness planning, not legal or compliance advice; validate against current regulation and your jurisdiction with qualified counsel.
An attorney pastes privileged communications or work product into a consumer AI tool whose terms permit training or retention. The disclosure can waive privilege and surface in discovery, and no policy or technical control stops it today.
AI invents case citations, statutes, or contract clauses that read as authoritative and reach a brief, opinion, or regulator without verification. Sanctions, malpractice exposure, and lost credibility follow when no QC checkpoint catches confidently wrong output.
AI-assisted analysis informs compliance determinations or client advice with no record of how it was used or checked. When a regulator or court asks how the conclusion was reached, the function cannot show a defensible, documented process.
Client confidential information, deal data, and personal data flow into AI tools outside enterprise environments with no retention controls or data-processing terms. This breaches confidentiality duties and data-protection law before anyone notices.
Legal and compliance write the firm's AI rules yet run their own AI use informally, with no written policy the team has read. The credibility gap undermines enforcement and surfaces in the first audit or incident.
Concrete first moves you can make before the full diagnostic, one per pillar where it matters most.
Write a one-page AI policy for the function that names approved tools, bans pasting privileged or client-confidential material into consumer tools, and have every lawyer and paralegal read it this week.
Require that every AI-assisted citation, clause, and factual assertion is verified against source before it enters a filing, memo, or compliance determination, and log that the check happened.
Audit each AI tool the function touches for data retention, training-on-input, confidentiality, and output-ownership terms, and retire or renegotiate any that put privilege or IP at risk.
Take a high-volume task like NDA review or first-pass research and document the exact step where AI plugs in, converting one person's prompts into a shared, versioned SOP the team applies.
Appoint one person to own legal AI capability with protected time, and run a role-specific session for paralegals and junior lawyers on safe, effective AI use in their actual workflows.
Move privileged and personal-data work into an enterprise AI environment with retention controls and a data-processing agreement, and block consumer tools for client matters.
The old transformation is finished. The new one is scored.